7.8
CVSSv2

CVE-2014-4018

Published: 16/07/2014 Updated: 16/07/2014
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote malicious users to obtain access via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zte zxv10_w300_firmware 1.0.0a_zrd_lk

zte zxv10_w300 -

Exploits

# Exploit Title: ZTE WXV10 W300 Multiple Vulnerabilities # Date: 17-05-2014 # Server Version: RomPager/407 UPnP/10 # Tested Routers: ZTE ZXV10 W300 # Firmware: W300V100a_ZRD_LK # ADSL Firmware: FwVer:3112175_TC3086 HwVer:T14F7_50 # Tested on: Kali Linux x86_64 # Exploit Author: Osanda Malith Jayathissa (@OsandaMalith) # Origin ...
ZTE WXV10 W300 suffers from suffers from backup disclosure, cross site request forgery, denial of service, and file disclosure vulnerabilities ...